The Identity Layer: Compliance as Core Crypto Infrastructure | Derek Woods - Persona
Ethereum Denver·Mon, Mar 9, 2026, 12:00 AM
This session reframes identity as a core infrastructure layer for crypto that is increasingly necessary for companies looking to reach mainstream users and integrate with the global financial system. We will cover what crypto companies need from identity and compliance to scale globally, where traditional KYC models fall short, and how better identity infrastructure can improve both user experience and regulatory outcomes.
Transcript
All right, welcome back. I'm excited to introduce our next guest speaker, Derek Woods, crypto lead at Persona. He's going to be talking about the identity layer compliance as core crypto infrastructure. Please welcome Derek.
Thanks everyone. Sorry for the technical difficulties, but we got there. Um, hi everyone. My name is Derek. Uh, as mentioned, crypto lead at Persona.
Really focused on helping, uh, Persona support the crypto industry here. Um, fun fact, I mean, I got into crypto back in 2017 and came to my first ETH Denver in 2023. So, back at the castle. I don't know if anyone remembers that one, but yeah, glad to be back. Anyways, today we're going to talk about crypto as identity infrastructure.
identity is becoming a more and more popular topic in crypto and especially as crypto is introduc or emerging with tradi that's really where persona has a lot of experience and we're trying to now figure out how to best support the crypto industry um as those worlds collide here especially from a compliance perspective so getting into it talking about compliance we're now seeing a ton of chatter online about this probably once a week I come across someone talking about we need better identity infrastructure we need a better KYC product out where we know people don't love cryp uh KYC um but our goal ultimately is to try and make this a lot better and we're hearing the noise out there. Our goal is to collaborate with everyone. For example, we have Bernardo Blind Pay down in Latin America making some great orchestration products uh who he calls out that Agentic compliance is going to become a thing and these are part people that we want to partner with to try and figure out how do we make this useful for them or even Stefan who's working at squads at XYZ or XYZ stablecoin neo banks is only as good as your compliance infrastructure. The reason why we see hear this theme come up more and more is because compliance infrastructure can be actually a bottleneck for like users going onto your platform. We know DeFi may not need compliance, but we're actually seeing a merging now of these these trends where for example, we know a is releasing an a app and a new on-ramp themselves.
This is now verging into the compliance world where now we're accessing mainstream users to DeFi kind of in like uh the the mullet method. So here we are. We think this compliance is going to become a real advantage towards getting ahead especially in like these modern uh compliance frameworks that are coming out and they are starting to come for crypto. So we know traditional finance had the bank secrecy act finsen enforcing KYC rules, bank uh KYB rules but we are now seeing adaptations of that for crypto. In Europe we have Mika being rolled out.
We also have genius act just approved. These are essentially updating those compliance rules for crypto or at least uh there's some elements within there. Um but beyond just traditional uh anti-moneyaundering and KYC, we're also noticing expanded rule sets like travel rule come out uh or even blockchain transaction monitoring. This stuff is what gets traditional finance comfortable with this technology to be used. Um but this also introduces a challenge for you all.
You're all trying to build great products. Uh, make the new DeFi frontier come to life, but how do we make it easy for you is really the challenge. We want to help you focus on building that and put the compliance to the side. Make that easy. But let's just show you some what we've identified as some of the key challenges.
And there's already some obvious solutions out there, but there's some new frontiers that we'll talk to, which is the nice big blue box here, which what what we're really excited about. Uh first off, crypto companies that do touch regulated rails or like on-ramps for example or exchanges face this global KYC challenge. The reason why we say global is a lot of these projects are default global. By the day you start you're launching to everyone. Um maybe some go slow and just trying to roll out country by country but ultimately this isn't meant to be confined to one country all these projects.
So a challenge is projects are born global complying with each of the regulations be it in Europe, North America, South America, APAC, additional challenges for you all. Um and then there's inconsistent uh policies in each of those regions. So not only are you trying to be compliant in each of those countries, but maybe the requirements and types of documentation that you collect or audit trails that you collect vary from country to country. Thankfully, there are solutions out there. For example, Persona is one of those supporting like all these global countries.
uh 200 different ids configurable uh jurisdictions that are or jurisdictional workflows that are customized to that region uh and then allows you to build you know document flows database checks anti-moneyaundering checks wherever those users are so that is essentially just adapting what's traditional finance is already used and we're just applying it now to crypto like neo banks um growing scope here is the also just like number regulations as I mentioned we need that flexibility we also believe that with ma coming in there might be adaptations to these rules that grow over time or modify over time. So, how do you remain flexible where your team is still busy working on building your project, you actually need to try and be ahead of it and say we need a part partner that can actually do a better job of like helping us stay on the forefront of compliance. It's tough because it keeps changing. Um, and a key part is that these checks are no longer just at onboarding. A lot of these regulations are mandating that you change that you do periodic checks every year um and do some level of like ongoing monitoring just checking if someone's been added to a watch list or uh have some adverse media.
Thankfully like this is feels like already solved for um we've configurable workflows realtime AML screening all that types of stuff. Um but it brings me to what we think is the biggest challenge and we've been hearing this the most. I've been uh talking to probably 20 companies a week for the past year and the challenge that I recurrenly hear is as neo banks built for neo banks is a great example where there's multiple providers within one application and that neo bankank may do KYC once and they may use an on-ramp provider they may use a uh an a bridge for example to exchange stable coins and a card issuer provider all of those partners what are they going to ask for KYC because they're regulated and this is where we entered the number one challenge we hear, which is duplicative KYC. And this is the number one stifler I think for user adoption hitting mainstream. Even if I use my Robin Hood app or Venmo app, I'm not asked for KYC multiple times within the same experience.
We all know that's horrible. So, how do we solve for this? This is what Persona is really trying to work on. Um, but let's like break it down a little further to figure out like why is this so difficult? Why hasn't someone come out with this already?
We've actually heard it. people try and make it uh a thing like reusable identity but nothing has really like taken off yet and there are a few reasons for it just to peel back uh the onion. One of the challenges is that each of those providers have their own interpretation of what is a compliance law. For example, someone in the uh one uh compliance leader at your on-ramp provider might decide you need to collect a valid form of ID that is fresh within the past year or another one might say we need to collect uh a proof of address document like a bank statement. And the challenge here is if those are different, how do you align them and how do you facilitate sharing of data?
We'll talk through how we can how we're thinking about this, but that's just a number one challenge that we're seeing. Um and that different criteria causes a lot of friction. That user may have already onboarded once and then they have to do it again because those were incompatible policies when it comes to uh their compliance uh policies. And then naturally user consent. Uh we want to be cautious about the privacy element here.
Uh we know we don't want to create a ton of honeypotss if we don't need to. Um but user does need to know where's their data going, which partners are touching it. Um, and that's something that we we really want to focus on is how do we still empower that end user to be sure that they're not just dishing their their data out everywhere. Um, and it's in a secure and privacy preserving manner. So, one of the solutions that we're thinking about is reusing verifiable credentials with a partner network.
Uh we'll get into a little bit more on how Persona is specifically thinking about it, but when it comes to reusing this identity data, uh we really think about um how do we make that a dynamic or progressive disclosure of identity information. And so anything that has been previously captured, the user can't consent to reusing that with one provider. So if I've onboarded to my neo bank, used an ID, uh I can say great, this is now saved with that neo bank. and the moment that I want to make a swap and potentially we use bridge let's say they would be able to facilitate a consent and share that data or maybe the next week I want to actually issue a card through Rain um Rain will also need to pass some compliance checks we can help facilitate the data transfer and potentially like progressive disclosure of additional documents if Rain has higher or more strict criteria than the original Neoank collected um all this is dynamic as it mentioned here shared data against uh it. Sorry.
The beauty of this is that each of those partners have their own policy and they can control what's being approved and what's not. As I mentioned, the challenge is that if the neo bank didn't perform a great KYC, the partners might not be able to rely on it. And if they're unable to rely on it, they might just trigger their own fresh KYC, which is a bad user experience. So, our goal here is really to like optimize that user experience. Um, and then all of this is like shared through secure tokenbased and consent driven data sharing, which we think is really important.
That's better for the user experience. But thinking about the operational side, I want is there any compliance people in here? I'm just curious. Probably not. Your compliance teams will appreciate this because it's it's helpful operationally.
Um it's how do we allow them to process more users if there is an escalation in their complian like imagine if someone does trigger uh an enhanced due diligence check where usually it means your compliance team is actually going on their computer looking at the watch list hits determining whether this is someone that they're comfortable with allowing on their platform. Um in this case they're able to process more data because some of the verifications have been performed already. Um, what that allows for if it's already been pre-approved, your compliance team now can onboard more users much quicker, allowing for better user experience as well. Uh, and a happier team and a smaller team. We know teams are very lean these days and so ultimately we want to uh not allow we want to allow you to bring on more users without growing your team.
Um, another bit is uh audit trails. So the companies nowadays, if they're trying to be a regulated entity, they may occasionally have to prove an audit that their compliance program is is robust or even to their sponsor bank and show their sponsor bank, hey, we are actually doing all the right steps here to ensure there's not money launderer on our platform. That type of thing. Um, audit trails are very important, especially when it comes to data sharing. If you're sharing data and not reverifying it, you also then are really just trusting that original provider that they've done a accurate check.
We think there's a time and place for that. Um, however, we see most companies that I speak to wanting to reverify that data each time it's been shared with them. So, they are ultimately responsible for whether that's an approved user or not. So, the solution here is um we help you ingest all that data into a compliance like system of record um in an accessible format which allows for data sharing if necessary only consent driven though naturally um and then trigger fallback flows. This fallback flow is key where it's that progressive disclosure.
If someone needs to now upload, they've already uploaded their ID or passport, but the next provider when they issue a card, let's say, needs a bank statement or a proof of address document, they can now only be presented with a screen to collect that. So, what does this actually look like in practice? Uh, this is where Persona in the past uh year and a half, we've really been working on this product called Connect um which is facilitating all this in a seamless way. low engineering lift, but ultimately there may be a source organization that wants to share with their destination or we could imagine even an unhosted wallet, let's pretend um where they actually say we want Persona to do KYC so all their partners that get used within it uh no longer need to ask for that KYC. Once again, making a great user experience and what that means is competitive advantage to the other projects out there.
because if you allow users to get on easier and provide a better user experience, users will flock. Um, so let's take a look at this. What we have is uh a fintech, let's say a neo bank uh is setting up their app. When you on board, you might do a KYC and then uh KYC, we see screens 22 through let's say 14, upload an ID, take a selfie, um we'll run some watch list checks behind the scenes, they're approved, all of a sudden they're in their wallet and now they want to fund it. One of our partners, Moonay, is an example of someone that would be using Persona.
And let's say they chose Moonay as their on-ramp provider. Neoank 1 can share or provide a popup that says, uh, would the user like to consent to share their previously collected data with their on-ramp provider. If they consent to yes, great. They share fully disclosing government ID, selfie, proof of address in this case. Great.
The user's been onboarded. uh and it feels pretty frictionless compared to potentially screen 17 would have ended up being you know 10 more screens if they didn't have this data sharing method. So immediately a better user experience and ideally uh when they go uh try and get get a card issued to the for themselves through the same neo bank they could do the exact same experience without this data sharing there's a chance that this really would have been a ton of KYC bad user experience someone might end up just churning and going to the next provider. So just to recap some of those like highlights, um this will increase conversion of your users on boarding and throughout the life cycle of them being on your platform. Uh still maintain full compliance.
Your compliance teams will be happy. Uh and then will help uh help you share data through tokenbased uh systems through persona and then also allows you a flexible range of integration options depending on like what integration your engineering team likes to use. But the value to the end user is minimal data collection across customer onboarding flows. I don't have to go find my passport every time I want to onboard or make a use a feature within my neo bank. And then it's all consent driven.
Uh which allows you also to redact your data at any point and so you're aware of who you're sharing data with which I think is important. Um persona's got a growing network of uh customers within crypto but also non-crypto. We know tradi is also emerging and so we think this is really important to build out this network where exchanges and brokerages uh such as Kraken or custodians uh crypto on-ramps and off-ramps infrastructure and DeFi all will be able to eventually share this data and uh make it really seamless for those end users to make more use of DeFi really we that's ultimately what we want uh and to make it easy but we do recognize that this is really like bringing crypto into web 2 which we don't love we want to think about what is next and what's the future so We're also participating in some exciting projects where we're working with chain link automated compliance engine um where smart contracts can determine whether a wallet has been verified verifiable credentials and att test stations where someone could actually KYC and receive a credential to their wallet if they want to participate let's say in bidd receive a token through them wallet signatures to prefer confirm ownership and then finally blockchain transaction monitoring all these elements are parts where persona is experimenting with um and we'd love to actually participate with some of you all builders and figure out how how can we do more in this space. So if this is any of this has resonated with you, please come and speak to me. We got some other persona folk here.
Uh we'd love to work together on finding the best solution to bring crypto to the masses while remaining compliant. Awesome. Thanks so much for your time.
Automatic transcript — names and jargon may be misspelled.